I don't see any vulnerability here. The -h option of 'chown -h A/B/C' does not affect whether A and A/B are followed if they are symbolic links: they are always followed, regardless of whether the -h option is specified. The -h option affects only whether A/B/C is followed if A/B/C is a symbolic link. This is a well-known property of symbolic links.
- bug#35654: We've found a vulnerability of gnu chown, please c... st0n3 ss
- bug#35654: please delete 35654 st0n3 ss
- bug#35654: markdown version. st0n3 ss
- bug#35654: We've found a vulnerability of gnu chown, ple... Paul Eggert
- bug#35654: We've found a vulnerability of gnu chown, ple... Assaf Gordon